CVE-2020-1180
published 2020-09-11CVE-2020-1180: A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory…
PriorityP343high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
2.07%
79.3th percentile
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
The security update addresses the vulnerability by modifying how the ChakraCore scripting engine handles objects in memory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | chakracore | < publication | publication |
| microsoft | chakracore | < 1.11.22 | 1.11.22 |
| microsoft | microsoft_edge | >= 1.0..0 < publication | publication |
| msrc | chakracore | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa8.1HIGH
osv8.1HIGH
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Remote code execution in ChakraCore
ghsa·2021-08-02·CVSS 8.1
CVE-2020-1180 [HIGH] CWE-787 Remote code execution in ChakraCore
Remote code execution in ChakraCore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1057, CVE-2020-1172.
GHSA
Remote code execution in ChakraCore
ghsa·2021-08-02·CVSS 7.5
CVE-2020-1057 [HIGH] CWE-119 Remote code execution in ChakraCore
Remote code execution in ChakraCore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1172, CVE-2020-1180.
OSV
Remote code execution in ChakraCore
osv·2021-08-02·CVSS 8.1
CVE-2020-1172 [HIGH] Remote code execution in ChakraCore
Remote code execution in ChakraCore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1057, CVE-2020-1180.
OSV
Remote code execution in ChakraCore
osv·2021-08-02·CVSS 8.1
CVE-2020-1180 [HIGH] Remote code execution in ChakraCore
Remote code execution in ChakraCore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1057, CVE-2020-1172.
GHSA
Remote code execution in ChakraCore
ghsa·2021-08-02·CVSS 8.1
CVE-2020-1172 [HIGH] CWE-787 Remote code execution in ChakraCore
Remote code execution in ChakraCore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1057, CVE-2020-1180.
OSV
Remote code execution in ChakraCore
osv·2021-08-02·CVSS 7.5
CVE-2020-1057 [HIGH] Remote code execution in ChakraCore
Remote code execution in ChakraCore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1172, CVE-2020-1180.
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2020-09-08·CVSS 4.2
CVE-2020-1180 [MEDIUM] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
The security update addresses the vulnerability by modifying how the ChakraCore scripting
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
blogs_tenable·2020-09-08
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-16711 ImageMagick: memory leak in Huffman2DEncodeImage in coders/ps2.c
bugzilla·2020-02-11·CVSS 6.5
CVE-2019-16711 [MEDIUM] CVE-2019-16711 ImageMagick: memory leak in Huffman2DEncodeImage in coders/ps2.c
CVE-2019-16711 ImageMagick: memory leak in Huffman2DEncodeImage in coders/ps2.c
A vulnerability was found in ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1542
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: epel-8 [bug 1801678]
Affects: fedora-all [bug 1801676]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick/commit/ba0e05ee5a983c202f1030c7901ed6b3ed7d652c
https://github.com/ImageMagick/ImageMagick6/commit/448f301a781405a45717bb53578475de06df973a
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates fo
Bugzilla
CVE-2019-16712 ImageMagick: memory leak in Huffman2DEncodeImage in coders/ps3.c
bugzilla·2020-02-11·CVSS 6.5
CVE-2019-16712 [MEDIUM] CVE-2019-16712 ImageMagick: memory leak in Huffman2DEncodeImage in coders/ps3.c
CVE-2019-16712 ImageMagick: memory leak in Huffman2DEncodeImage in coders/ps3.c
A vulnerability was found in ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1557
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: epel-8 [bug 1801679]
Affects: fedora-all [bug 1801677]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick/commit/7b04c53c69792243d66d6876f843b850b3cc002b
https://github.com/ImageMagick/ImageMagick6/commit/451d0e4aadb17f16d15006aed379b71714d04a5d
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug
Bugzilla
CVE-2019-19948 ImageMagick: heap-based buffer overflow in WriteSGIImage in coders/sgi.c
bugzilla·2020-01-20·CVSS 9.8
CVE-2019-19948 [CRITICAL] CVE-2019-19948 ImageMagick: heap-based buffer overflow in WriteSGIImage in coders/sgi.c
CVE-2019-19948 ImageMagick: heap-based buffer overflow in WriteSGIImage in coders/sgi.c
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1562
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: epel-8 [bug 1793178]
Affects: fedora-all [bug 1793179]
---
Upstream fix:
https://github.com/ImageMagick/ImageMagick6/commit/9e7db22f8c374301db3f968757f0d08070fd4e54
---
ImageMagick 7 commit:
https://github.com/ImageMagick/ImageMagick/commit/6ae32a9038e360b3491969d5d03d490884f02b4c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This
Bugzilla
CVE-2019-14981 ImageMagick: division by zero in MeanShiftImage in MagickCore/feature.c
bugzilla·2019-10-02·CVSS 6.5
CVE-2019-14981 [MEDIUM] CVE-2019-14981 ImageMagick: division by zero in MeanShiftImage in MagickCore/feature.c
CVE-2019-14981 ImageMagick: division by zero in MeanShiftImage in MagickCore/feature.c
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/commit/a77d8d97f5a7bced0468f0b08798c83fb67427bc
https://github.com/ImageMagick/ImageMagick/issues/1552
https://github.com/ImageMagick/ImageMagick6/commit/b522d2d857d2f75b659936b59b0da9df1682c256
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1770647]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-20
Bugzilla
CVE-2019-12979 imagemagick: use of uninitialized value in functionSyncImageSettings in MagickCore/image.c
bugzilla·2019-07-23·CVSS 7.8
CVE-2019-12979 [HIGH] CVE-2019-12979 imagemagick: use of uninitialized value in functionSyncImageSettings in MagickCore/image.c
CVE-2019-12979 imagemagick: use of uninitialized value in functionSyncImageSettings in MagickCore/image.c
A vulnerability was found in ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the
SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1522
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1732295]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick/commit/ee3dae8624e69261760754442827aea4d0254a6f
https://github.com/ImageMagick/ImageMagick6/commit/27b1c74979ac473a430e266ff6c4b645664bc805
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 ht
Bugzilla
CVE-2019-12975 imagemagick: memory leak vulnerability in function WriteDPXImage in coders/dpx.c
bugzilla·2019-07-23·CVSS 5.5
CVE-2019-12975 [MEDIUM] CVE-2019-12975 imagemagick: memory leak vulnerability in function WriteDPXImage in coders/dpx.c
CVE-2019-12975 imagemagick: memory leak vulnerability in function WriteDPXImage in coders/dpx.c
ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage
function in coders/dpx.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1517
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1732283]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/b9c3aa197020ca091a21145cf46855afd4ddcb07
https://github.com/ImageMagick/ImageMagick/commit/ee5b9c56b9ca18ed0750f8a15e0d1a6da92a6e99
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products w
Bugzilla
CVE-2019-12976 imagemagick: memory leak vulnerability in function ReadPCLImage in coders/pcl.c
bugzilla·2019-07-23·CVSS 5.5
CVE-2019-12976 [MEDIUM] CVE-2019-12976 imagemagick: memory leak vulnerability in function ReadPCLImage in coders/pcl.c
CVE-2019-12976 imagemagick: memory leak vulnerability in function ReadPCLImage in coders/pcl.c
A vulnerability was found in ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in
coders/pcl.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1520
Upstream fix:
https://github.com/ImageMagick/ImageMagick6/commit/ff840181f631b1b7f29160cae24d792fcd176bae
https://github.com/ImageMagick/ImageMagick/commit/c0fe488e7052f68d4eb7768805a857ef6fef928d
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1732285]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual produc
Bugzilla
CVE-2019-12978 imagemagick: use of uninitialized value in function ReadPANGOImage in coders/pango.c
bugzilla·2019-07-23·CVSS 7.8
CVE-2019-12978 [HIGH] CVE-2019-12978 imagemagick: use of uninitialized value in function ReadPANGOImage in coders/pango.c
CVE-2019-12978 imagemagick: use of uninitialized value in function ReadPANGOImage in coders/pango.c
A vulnerability was found in ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the
ReadPANGOImage function in coders/pango.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1519
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1732293]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick/commit/ee60b346b8fce70eb3b239a78e2486fba9615069
https://github.com/ImageMagick/ImageMagick6/commit/ae1ded6140bfa8ae9f6dcba5413b72d98ed94614
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is
Bugzilla
CVE-2019-13300 ImageMagick: heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns
bugzilla·2019-07-17·CVSS 8.8
CVE-2019-13300 [HIGH] CVE-2019-13300 ImageMagick: heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns
CVE-2019-13300 ImageMagick: heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1586
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730581]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick/commit/a906fe9298bf89e01d5272023db687935068849a
https://github.com/ImageMagick/ImageMagick6/commit/5e409ae7a389cdf2ed17469303be3f3f21cec450
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:11
Bugzilla
CVE-2019-13301 ImageMagick: memory leaks in AcquireMagickMemory
bugzilla·2019-07-17·CVSS 6.5
CVE-2019-13301 [MEDIUM] CVE-2019-13301 ImageMagick: memory leaks in AcquireMagickMemory
CVE-2019-13301 ImageMagick: memory leaks in AcquireMagickMemory
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1585
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730576]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/f595a1985233c399a05c0c37cc41de16a90dd025
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/0b7d3675438cbcde824e751895847a0794406e08
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products w
Bugzilla
CVE-2019-13304 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment
bugzilla·2019-07-16·CVSS 7.8
CVE-2019-13304 [HIGH] CVE-2019-13304 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment
CVE-2019-13304 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1614
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730365]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/bfa3b9610c83227894c92b0d312ad327fceb6241
https://github.com/ImageMagick/ImageMagick/commit/7689875ef64f34141e7292f6945efdf0530b4a5e
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This
Bugzilla
CVE-2019-13310 ImageMagick: memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c
bugzilla·2019-07-16·CVSS 6.5
CVE-2019-13310 [MEDIUM] CVE-2019-13310 ImageMagick: memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c
CVE-2019-13310 ImageMagick: memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1616
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730334]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/5f21230b657ccd65452dd3d94c5b5401ba691a2d
https://github.com/ImageMagick/ImageMagick6/commit/5982632109cad48bc6dab867298fdea4dea57c51
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates
Bugzilla
CVE-2019-13306 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors
bugzilla·2019-07-16·CVSS 7.8
CVE-2019-13306 [HIGH] CVE-2019-13306 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors
CVE-2019-13306 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1612
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730359]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/cb5ec7d98195aa74d5ed299b38eff2a68122f3fa
https://github.com/ImageMagick/ImageMagick/commit/e92040ea6ee2a844ebfd2344174076795a4787bd
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now
Bugzilla
CVE-2019-13307 ImageMagick: heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows
bugzilla·2019-07-16·CVSS 7.8
CVE-2019-13307 [HIGH] CVE-2019-13307 ImageMagick: heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows
CVE-2019-13307 ImageMagick: heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1615
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730352]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/91e58d967a92250439ede038ccfb0913a81e59fe
https://github.com/ImageMagick/ImageMagick/commit/025e77fcb2f45b21689931ba3bf74eac153afa48
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
--
Bugzilla
CVE-2019-13309 ImageMagick: memory leaks at AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages
bugzilla·2019-07-16·CVSS 6.5
CVE-2019-13309 [MEDIUM] CVE-2019-13309 ImageMagick: memory leaks at AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages
CVE-2019-13309 ImageMagick: memory leaks at AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1616
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730338]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/5982632109cad48bc6dab867298fdea4dea57c51
https://github.com/ImageMagick/ImageMagick/commit/5f21230b657ccd65452dd3d94c5b5401ba691a2d
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.re
Bugzilla
CVE-2019-13311 ImageMagick: memory leaks at AcquireMagickMemory because of a wand/mogrify.c error
bugzilla·2019-07-16·CVSS 6.5
CVE-2019-13311 [MEDIUM] CVE-2019-13311 ImageMagick: memory leaks at AcquireMagickMemory because of a wand/mogrify.c error
CVE-2019-13311 ImageMagick: memory leaks at AcquireMagickMemory because of a wand/mogrify.c error
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
Upstream Issues:
https://github.com/ImageMagick/ImageMagick/issues/1623
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730331]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/4a334bbf5584de37c6f5a47c380a531c8c4b140a
https://github.com/ImageMagick/ImageMagick6/commit/bb812022d0bc12107db215c981cab0b1ccd73d91
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual pro
Bugzilla
CVE-2019-13454 ImageMagick: division by zero in RemoveDuplicateLayers in MagickCore/layer.c
bugzilla·2019-07-10·CVSS 6.5
CVE-2019-13454 [MEDIUM] CVE-2019-13454 ImageMagick: division by zero in RemoveDuplicateLayers in MagickCore/layer.c
CVE-2019-13454 ImageMagick: division by zero in RemoveDuplicateLayers in MagickCore/layer.c
ImageMagick 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1629
Upstream commit:
https://github.com/ImageMagick/ImageMagick/commit/1ddcf2e4f28029a888cadef2e757509ef5047ad8
https://github.com/ImageMagick/ImageMagick6/commit/4f31d78716ac94c85c244efcea368fea202e2ed4
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1728475]
---
The Division by Zero is caused by curr->ticks_per_second being 0 in RemoveDuplicateLayers().
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/
Bugzilla
CVE-2019-13135 ImageMagick: a "use of uninitialized value" vulnerability in the function ReadCUTImage leading to a crash and DoS
bugzilla·2019-07-02·CVSS 8.8
CVE-2019-13135 [HIGH] CVE-2019-13135 ImageMagick: a "use of uninitialized value" vulnerability in the function ReadCUTImage leading to a crash and DoS
CVE-2019-13135 ImageMagick: a "use of uninitialized value" vulnerability in the function ReadCUTImage leading to a crash and DoS
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1599
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1726108]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/cdb383749ef7b68a38891440af8cc23e0115306d
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/1e59b29e520d2beab73e8c78aacd5f1c0d76196d
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errat
Bugzilla
CVE-2019-13134 ImageMagick: a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c
bugzilla·2019-07-02·CVSS 5.5
CVE-2019-13134 [MEDIUM] CVE-2019-13134 ImageMagick: a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c
CVE-2019-13134 ImageMagick: a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1600
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1726082]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/fe3066122ef72c82415811d25e9e3fad622c0a99
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/210474b2fac6a661bfa7ed563213920e93e76395
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now cl
Bugzilla
CVE-2019-13133 ImageMagick: a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c
bugzilla·2019-07-02·CVSS 5.5
CVE-2019-13133 [MEDIUM] CVE-2019-13133 ImageMagick: a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c
CVE-2019-13133 ImageMagick: a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1600
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1726079]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/fe3066122ef72c82415811d25e9e3fad622c0a99
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/210474b2fac6a661bfa7ed563213920e93e76395
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed
Bugzilla
CVE-2019-7397 ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
bugzilla·2019-02-05·CVSS 7.5
CVE-2019-7397 [HIGH] CVE-2019-7397 ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
CVE-2019-7397 ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
In ImageMagick before 7.0.8-25, several memory leaks exist in WritePDFImage in coders/pdf.c.
References:
https://github.com/ImageMagick/ImageMagick/commit/306c1f0fa5754ca78efd16ab752f0e981d4f6b82
https://github.com/ImageMagick/ImageMagick/issues/1454
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1672590]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/306c1f0fa5754ca78efd16ab752f0e981d4f6b82
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/3b28c8d93aa469f6d90c8b3c05fe3d88c2584e32
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redh
Bugzilla
CVE-2019-7398 ImageMagick: Memory leak in the WriteDIBImage function in coders/dib.c
bugzilla·2019-02-05·CVSS 7.5
CVE-2019-7398 [HIGH] CVE-2019-7398 ImageMagick: Memory leak in the WriteDIBImage function in coders/dib.c
CVE-2019-7398 ImageMagick: Memory leak in the WriteDIBImage function in coders/dib.c
In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1453
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1672590]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/9cf2f738f714eba6d47be1127ed255acd2b51750
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/dfa1e752bce7b6994765897fb6606d6069345442
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual product
Bugzilla
CVE-2018-16750 ImageMagick: Memory leak in the formatIPTCfromBuffer function in coders/meta.c
bugzilla·2018-09-11·CVSS 6.5
CVE-2018-16750 [MEDIUM] CVE-2018-16750 ImageMagick: Memory leak in the formatIPTCfromBuffer function in coders/meta.c
CVE-2018-16750 ImageMagick: Memory leak in the formatIPTCfromBuffer function in coders/meta.c
In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
Upstream issue:
https://github.com/ImageMagick/ImageMagick/issues/1118
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1627919]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/33d1b9590c401d4aee666ffd10b16868a38cf705 [ImageMagick]
https://github.com/ImageMagick/ImageMagick6/commit/359331c61193138ce2b85331df25235b81499cfc [ImageMagick6]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now cl
Bugzilla
CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c
bugzilla·2018-09-03·CVSS 9.8
CVE-2018-16328 [CRITICAL] CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c
CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c
A flaw was found in ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1224
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1624956]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/107ce8577e818cf4801e5a59641cb769d645cc95
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://ac
Bugzilla
CVE-2018-14436 ImageMagick: memory leak in ReadMIFFImage in coders/miff.c
bugzilla·2018-07-30·CVSS 6.5
CVE-2018-14436 [MEDIUM] CVE-2018-14436 ImageMagick: memory leak in ReadMIFFImage in coders/miff.c
CVE-2018-14436 ImageMagick: memory leak in ReadMIFFImage in coders/miff.c
A flaw was found in ImageMagick 7.0.8-4. A memory leak in ReadMIFFImage in coders/miff.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1191
Upstream Patch:
https://github.com/ImageMagick/ImageMagick6/commit/ae3eecad2f59e27123c1a6c891be75d06fc03656
https://github.com/ImageMagick/ImageMagick/commit/4b352c0be410ad900469a079e389178f878aded8
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1609940]
---
Memory allocated in WriteMIFFImage and referenced by colormap is not released in case image depth is not an accepted value.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/
Bugzilla
CVE-2018-14434 ImageMagick: memory leak for a colormap in WriteMPCImage in coders/mpc.c
bugzilla·2018-07-30·CVSS 6.5
CVE-2018-14434 [MEDIUM] CVE-2018-14434 ImageMagick: memory leak for a colormap in WriteMPCImage in coders/mpc.c
CVE-2018-14434 ImageMagick: memory leak for a colormap in WriteMPCImage in coders/mpc.c
A flaw was found in ImageMagick 7.0.8-4. A memory leak for a colormap in WriteMPCImage in coders/mpc.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1192
Upstream Patch:
https://github.com/ImageMagick/ImageMagick/commit/98a2cceae0dceccbfe54051167c2c80be1f13c3f
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1609934]
---
Memory allocated in WriteMPCImage and referenced by colormap is not released in case image depth is not an accepted value.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updat
Bugzilla
CVE-2017-18273 ImageMagick: infinite loop ReadTXTImage in function in coders/txt.c
bugzilla·2018-05-22·CVSS 6.5
CVE-2017-18273 [MEDIUM] CVE-2017-18273 ImageMagick: infinite loop ReadTXTImage in function in coders/txt.c
CVE-2017-18273 ImageMagick: infinite loop ReadTXTImage in function in coders/txt.c
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.
References:
https://github.com/ImageMagick/ImageMagick/issues/910
Patch:
https://github.com/ImageMagick/ImageMagick/commit/d95991f24d27dbc335dfa7c0523c886ab9329e9e
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1581487]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bu
Bugzilla
CVE-2017-18271 ImageMagick: infinite loop in ReadMIFFImage function in coders/miff.c
bugzilla·2018-05-22·CVSS 6.5
CVE-2017-18271 [MEDIUM] CVE-2017-18271 ImageMagick: infinite loop in ReadMIFFImage function in coders/miff.c
CVE-2017-18271 ImageMagick: infinite loop in ReadMIFFImage function in coders/miff.c
A flaw was found in ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
References:
https://github.com/ImageMagick/ImageMagick/issues/911
Patch:
https://github.com/ImageMagick/ImageMagick/commit/7523250e2664028aa1d8f02d2d7ae49c769a851e
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1581487]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Furthe
Bugzilla
CVE-2018-10804 ImageMagick: Memory leak in WriteTIFFImage
bugzilla·2018-05-11·CVSS 6.5
CVE-2018-10804 [MEDIUM] CVE-2018-10804 ImageMagick: Memory leak in WriteTIFFImage
CVE-2018-10804 ImageMagick: Memory leak in WriteTIFFImage
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1053
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1577400]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-10804
Bugzilla
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
bugzilla·2018-05-11·CVSS 6.5
CVE-2018-10805 [MEDIUM] CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1054
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1577400]
---
Doesn't look like it's leaking canvas_image but definitely leaking quantum_info.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-10805
Bugzilla
CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
bugzilla·2018-04-26·CVSS 6.5
CVE-2018-10177 [MEDIUM] CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
ImageMagick through version 7.0.7-28 is vulnerable to an infinite loop in coders/png.c:ReadOneMNGImage(). An attacker could exploit this to cause a denial of service via crafted MNG file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1095
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1572045]
---
Upstream commit:
https://github.com/ImageMagick/ImageMagick6/commit/9eda4b36a8695e4a0cd27bea28b9c173c68a01ec
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now clo
Bugzilla
CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
bugzilla·2018-04-05·CVSS 6.5
CVE-2018-9133 [MEDIUM] CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
A flaw was found in ImageMagick 7.0.7-26 Q16. An excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1072
Patch:
https://github.com/ImageMagick/ImageMagick/commit/089fca04e0130549fa15f48ace3f56e30a06049a
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180
Bugzilla
CVE-2017-18252 ImageMagick: assertion failure in MogrifyImageList function in MagickWand/mogrify.c
bugzilla·2018-03-28·CVSS 6.5
CVE-2017-18252 [MEDIUM] CVE-2017-18252 ImageMagick: assertion failure in MogrifyImageList function in MagickWand/mogrify.c
CVE-2017-18252 ImageMagick: assertion failure in MogrifyImageList function in MagickWand/mogrify.c
An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/issues/802
Patches:
https://github.com/ImageMagick/ImageMagick/commit/bb04ccb34fd45e9c3020786857fb79b09f44d7db
https://github.com/ImageMagick/ImageMagick/commit/12f34b60564de1cbec08e23e2413dab5b64daeb7
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 h
Bugzilla
CVE-2017-18254 ImageMagick: memory leak in WriteGIFImage function in coders/gif.c
bugzilla·2018-03-28·CVSS 6.5
CVE-2017-18254 [MEDIUM] CVE-2017-18254 ImageMagick: memory leak in WriteGIFImage function in coders/gif.c
CVE-2017-18254 ImageMagick: memory leak in WriteGIFImage function in coders/gif.c
An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/issues/808
Patches:
https://github.com/ImageMagick/ImageMagick/commit/24d5699753170c141b46816284430516c2d48fed
https://github.com/ImageMagick/ImageMagick/commit/53ea13989003cdb4955024f95b4a0158a2e871c6
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2017-18251 ImageMagick: memory leak in ReadPCDImage function in coders/pcd.c
bugzilla·2018-03-28·CVSS 6.5
CVE-2017-18251 [MEDIUM] CVE-2017-18251 ImageMagick: memory leak in ReadPCDImage function in coders/pcd.c
CVE-2017-18251 ImageMagick: memory leak in ReadPCDImage function in coders/pcd.c
An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/issues/809
Patches:
https://github.com/ImageMagick/ImageMagick/commit/12a43437fec6f9245327636dc2730863bb9fdd8b
https://github.com/ImageMagick/ImageMagick/commit/99718b41102f26f802311045e882aa947ef2941b
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-20
2020-09-11
Published